VYPR

Ciges

by ATISoluciones

CVEs (8)

  • CVE-2025-1751CriFeb 27, 2025
    risk 0.64cvss 9.8epss 0.00

    A SQL Injection vulnerability has been found in Ciges 2.15.5 from ATISoluciones. This vulnerability allows an attacker to retrieve, create, update and delete database via $idServicio parameter in /modules/ajaxBloqueaCita.php endpoint.

  • CVE-2024-2724CriMar 22, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in the CIGESv2 system, through /ajaxServiciosAtencion.php, in the 'idServicio' parameter. The exploitation of this vulnerability could allow a remote user to retrieve all data stored in the database by sending a specially crafted SQL query.

  • CVE-2024-2723CriMar 22, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in the CIGESv2 system, through /ajaxSubServicios.php, in the 'idServicio' parameter. The exploitation of this vulnerability could allow a remote user to retrieve all data stored in the database by sending a specially crafted SQL query.

  • CVE-2024-2722CriMar 22, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in the CIGESv2 system, through /ajaxConfigTotem.php, in the 'id' parameter. The exploitation of this vulnerability could allow a remote user to retrieve all data stored in the database by sending a specially crafted SQL query.

  • CVE-2024-2725HigMar 22, 2024
    risk 0.49cvss 7.5epss 0.01

    Information exposure vulnerability in the CIGESv2 system. A remote attacker might be able to access /vendor/composer/installed.json and retrieve all installed packages used by the application.

  • CVE-2024-2727MedMar 22, 2024
    risk 0.40cvss 6.1epss 0.00

    HTML injection vulnerability affecting the CIGESv2 system, which allows an attacker to inject arbitrary code and modify elements of the website and email confirmation message.

  • CVE-2024-2726MedMar 22, 2024
    risk 0.40cvss 6.1epss 0.00

    Stored Cross-Site Scripting (Stored-XSS) vulnerability affecting the CIGESv2 system, allowing an attacker to execute and store malicious javascript code in the application form without prior registration.

  • CVE-2024-2728MedMar 22, 2024
    risk 0.27cvss 4.1epss 0.00

    Information exposure vulnerability in the CIGESv2 system. This vulnerability could allow a local attacker to intercept traffic due to the lack of proper implementation of the TLS protocol.